We use cookies

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. You can also customize your preferences or reject non-essential cookies. Learn more about our cookie policy

    Who's holding encryption keys for the software that you use?
    Uncategorized

    Who's holding encryption keys for the software that you use?

    Key Highlights:

    • Cloud Storage:

    Microsoft OneDrive: Microsoft controls keys by default but offers "Customer Key" for more control.

    • Google Drive: Google manages keys unless you pay for advanced options like Cloud EKM (€3.00 per key).

    • Dropbox: Keys are managed by Dropbox, with advanced options for enterprises.

    • Hypervault: Full user control with zero-knowledge encryption.

    • Messaging Services:

    WhatsApp: End-to-end encryption (E2EE) by default; users control private keys.

    • Telegram: Only "Secret Chats" use E2EE; regular chats are server-encrypted.

    • Signal: Full E2EE with user-controlled keys; no server access.

    • Facebook Messenger: E2EE by default for personal chats, but metadata is still collected.

    • Microsoft Teams: Offers E2EE for one-to-one calls; keys are Microsoft-managed unless you use "Customer Key".

    • Slack: No E2EE; encryption keys are managed by Slack unless you use Enterprise Key Management (EKM).

    Quick Comparison (Encryption & Key Management):

    ServiceEncryption TypeKey ManagementEnd-to-End Encryption (E2EE)GDPR Compliance
    OneDriveAES-256 + TLSMicrosoft or Customer KeyNoYes
    Google DriveAES-256 + TLSGoogle or Cloud EKM (paid)NoYes
    DropboxAES-256 + TLSDropbox or AWS KMS (enterprise)NoYes
    HypervaultAES-256 (zero-knowledge)User-controlledYesYes
    WhatsAppSignal Protocol (E2EE)User-controlledYesYes
    TelegramMTProto 2.0Telegram (except Secret Chats)PartialYes
    SignalSignal Protocol (E2EE)User-controlledYesYes
    MessengerSignal + Labyrinth ProtocolUser-controlled (personal chats)PartialYes
    TeamsTLS/SRTPMicrosoft or Customer KeyPartial (1:1 calls only)Yes
    SlackTLSSlack or AWS KMS (enterprise)NoYes

    Key Takeaway:

    For maximum privacy, choose services with end-to-end encryption and user-controlled keys. Platforms like Signal, Hypervault, and WhatsApp stand out. If you're using enterprise tools like Teams or Slack, explore options like "Customer Key" or "Enterprise Key Management" for better control.

    Keys to the kingdom: Everything you need to know about your encryption keys

    To view this YouTube video, please accept marketing cookies.

    1. Microsoft OneDrive

    Microsoft OneDrive

    Microsoft OneDrive uses a multi-layered encryption approach, but the company retains control over its encryption keys. While this ensures robust protection, it raises some concerns about privacy and security.

    Here’s how OneDrive safeguards your data:

    • Data in transit: Protected with TLS encryption using 2048-bit keys [1].

    • Data at rest: Secured with BitLocker and per-file AES256 encryption. The master keys are stored in Azure Key Vault [4].

    Microsoft has introduced its EU Data Boundary initiative [6], aiming to address data sovereignty concerns. However, it’s important to note that Microsoft retains the ability to decrypt data for legal, maintenance, or law enforcement purposes [7].

    "OneDrive and Office 365 maintain a 'zero-standing access' policy, which means that engineers do not have access to the service unless it is explicitly granted in response to a specific incident that requires elevation of access." – Microsoft Support [4]

    Key Security Considerations

    AspectSecurity Consideration
    Key ControlMicrosoft manages encryption keys.
    Data AccessData can be decrypted for legal or maintenance purposes.
    Metadata ExposureFile names and modification dates may be visible.
    Geographic StorageComplies with EU Data Boundary regulations.

    Microsoft 365 achieved ISO 27001/27017 certification in March 2022 [5]. Additionally, organisations using Azure Key Vault can opt for the Customer Key feature, allowing them to supply and manage their own root encryption keys [2].

    For Belgian users, strengthening account security is crucial. Recommended measures include enabling two-factor authentication, enforcing strong password policies, using Mobile Device Management tools, and activating audit logging features.

    It’s worth noting that Microsoft’s centralised key management means they technically have access to encrypted content [8]. This, combined with the fact that human errors account for 85% of data breaches [9], underscores the importance of implementing additional security measures.

    This overview of OneDrive provides a foundation for comparing encryption and key management practices across other cloud storage services.

    2. Google Drive

    Google Drive

    Google Drive employs AES-256 encryption to secure data both at rest and during transmission, with encryption keys managed by Google by default.

    Standard Encryption Implementation

    Google Workspace applies encryption across the board:

    • Data at rest: Secured using AES-256 encryption.

    • Data in transit: Protected while moving between Google facilities.

    • Key management: By default, Google manages encryption keys.

    For users who need more control, Google offers flexible key management options:

    Key Management OptionControl LevelCost per MonthKey Ownership
    Auto/Manual Cloud KMSAutomated + Manual Control€0.06 per key versionCustomer
    Manual Cloud KMSFull Manual Control€0.06 per key versionCustomer
    Cloud EKMMaximum Control€3.00 per key versionCustomer

    Enterprise Security Features

    For organisations requiring tighter control, Google Workspace offers Client-side Encryption (CSE). This feature encrypts data directly in the user's browser before it’s sent to Google’s servers. As a result, decryption keys remain out of Google’s reach, ensuring that only authorised users can access the data.

    Security Vulnerabilities and Risks

    While encryption is a major safeguard, other security risks persist. Recent findings highlight several vulnerabilities:

    • 40% of Google Drive content contains sensitive information [11].

    • 73% of employees have access to data beyond their authorisation level [11].

    • Approximately 94,000 assets often remain exposed to former employees [12].

    Essential Security Measures

    To address these risks, organisations should adopt the following practices:

    • Implement Access ControlsEnforce strict access policies and conduct regular permission audits to comply with EU data protection laws.

    • Enable Advanced Security FeaturesUse tools like CASB (Cloud Access Security Broker) and IRM (Information Rights Management) to prevent unauthorised sharing or downloads.

    • Monitor User BehaviourSet up email alerts for suspicious activities and routinely review third-party OAuth apps that access Google Drive.

    For Belgian organisations bound by GDPR, Google provides robust compliance tools, including Data Processing Agreements (DPA) and Standard Contractual Clauses (SCCs). Additionally, Google’s certifications - ISO/IEC 27001, 27017, 27018, and 27701 - underscore its dedication to maintaining high data protection standards [10]. These layered security options reflect a balance between ease of use and maintaining control.

    3. Dropbox

    Dropbox

    Dropbox employs multi-layered encryption to secure user data, while retaining control over encryption keys for standard accounts. This approach allows for lawful or policy-driven access when required [16].

    Standard Security Measures

    Dropbox protects files at rest using 256-bit AES encryption. Data in transit is secured through SSL/TLS protocols, ensuring a high level of security during transfers [13]. Business users benefit from additional encryption features that bolster this baseline protection.

    Enterprise Encryption Features

    For customers using Dropbox Advanced, Business Plus, or Enterprise plans, a robust security framework incorporates key management and team-level controls:

    FeatureImplementationKey Management
    Advanced EncryptionAWS Key Management ServiceHardware Security Modules
    Team Key RotationAutomaticEvery 12 months
    Key RevocationPermanentRemoves all access
    Device RegistrationAutomated/ManualTeam-controlled

    Key Management Approach

    Dropbox's enterprise-level encryption revolves around a team-focused approach [17]. Top-level encryption keys are created and managed through Amazon Web Services Key Management Service (AWS KMS), utilising Hardware Security Modules (HSM) [15]. This infrastructure provides advanced security while maintaining operational efficiency.

    Recent Security Incident

    In May 2024, Dropbox Sign experienced a cyber attack that resulted in unauthorised access to data [16]. This incident underscores the importance of ongoing security enhancements to combat evolving threats.

    Practical Security Tips

    To complement Dropbox's encryption and key management measures, consider adopting these additional security practices:

    • Enable two-factor authentication for an extra layer of login security [13].

    • Use a VPN when accessing Dropbox over public Wi-Fi networks [14].

    • Regularly monitor account activity to detect any unusual behaviour [14].

    • Keep your applications updated to ensure you have the latest security patches [14].

    For users seeking full control over encryption, tools like Cryptomator can be used to pre-encrypt files before uploading them to Dropbox [13].

    4. Hypervault

    Hypervault

    Hypervault employs zero-knowledge encryption to give users full control over their data, meeting both Belgian regulations and GDPR standards.

    Zero-Knowledge Architecture

    Hypervault’s zero-knowledge protocol ensures that only authorised users can access their data vaults. By encrypting data locally on the user’s device before it is transmitted, the platform guarantees that no one else - not even Hypervault - can view the encrypted information [20][18].

    Encryption Implementation

    Security LayerImplementationUser Benefit
    Data EncryptionAES-256 bitHigh-level protection
    Key StorageStored client-sideUsers maintain full control
    Server LocationEU datacentresGDPR-compliant infrastructure
    AuthenticationMulti-factorStronger access security
    Access ControlAzure AD integrationSimplified centralised management

    These layers form the backbone of Hypervault’s commitment to European data security standards.

    EU Data Protection Measures

    All data managed by Hypervault is hosted within EU datacentres [18]. This aligns with GDPR requirements, a critical safeguard given that €1.64 billion in fines were issued for data breaches across Europe in 2022 [19]. By adhering to these measures, Hypervault strengthens operational security for businesses.

    Enterprise Security Features

    Hypervault offers several advanced security features tailored for enterprises:

    • Zero Server Access: Hypervault’s infrastructure is designed so that it cannot decrypt or access user data [18].

    • Improved Password Security: Enhanced protocols minimise risks from weak passwords [19].

    • Azure Integration: Provides seamless single sign-on functionality for enterprise environments.

    Data Residency and Compliance

    Hypervault ensures that all sensitive data remains within EU borders, supporting compliance with GDPR regulations, including Article 32 [18][19]. Its zero-knowledge architecture adds an extra layer of security, protecting user data even in the unlikely event of a server breach. With rigorous key management practices, Hypervault prioritises privacy, making it a dependable choice for enterprises aiming to safeguard their data.

    5. WhatsApp

    WhatsApp

    WhatsApp ensures all communications - messages, photos, videos, voice messages, documents, status updates, and calls - are protected with end-to-end encryption (E2EE) by default. This encryption system plays a crucial role in safeguarding user data [21].

    Key Management and Encryption

    To manage encryption keys effectively, WhatsApp relies on the Signal Protocol, which incorporates Curve25519, AES-256, and HMAC-SHA256 [23]. Messages are encrypted directly on the sender's device, ensuring only the intended recipient can decrypt them [21][23]. The system uses two distinct types of keys:

    Key TypeLocationAccess Control
    Public KeysWhatsApp ServersShared with message senders
    Private KeysUser DevicesControlled solely by the user

    This setup ensures a secure and private communication channel.

    Data Collection and Privacy

    While WhatsApp encrypts message content, it still collects metadata such as IP addresses, phone numbers, timestamps, contact interaction patterns, and device information [24].

    "Protecting content is only half the battle. Who you communicate [with] and when is the other half." [24]

    This highlights the importance of addressing both content security and metadata privacy.

    Security Considerations

    Despite its robust encryption, WhatsApp has faced security challenges. In early 2024, a significant breach exposed over 300 million records, including 21,000 phone numbers and 31,000 email addresses [23]. To address such vulnerabilities, WhatsApp introduced key transparency features that automatically verify secure connections [22].

    Backup Security

    For added data protection, WhatsApp provides end-to-end encrypted backups for cloud storage on Google Drive and iCloud. Users can secure these backups with a 64-digit encryption key or a password of their choice [25][26].

    Verification Measures

    WhatsApp offers multiple ways for users to confirm their connection security:

    • Automatic key transparency checks

    • Manual security code verification with contacts

    • Two-step verification for an added layer of protection

    These measures strengthen the platform's security framework, ensuring users can communicate with confidence.

    6. Telegram

    Telegram

    Telegram employs two distinct encryption methods: regular cloud chats use client–server encryption, while Secret Chats rely on end-to-end encryption, powered by the MTProto 2.0 protocol.

    Regular Cloud Chats vs. Secret Chats

    Telegram's two chat types differ significantly in how they handle security and accessibility:

    FeatureRegular Cloud ChatsSecret Chats
    Encryption TypeClient–server encryptionEnd-to-end encryption
    Key StorageStored on Telegram's serversStored on users' devices
    Cloud AccessAccessible across devicesLimited to specific devices
    Message StorageStored on serversNot stored on servers

    These distinctions form the foundation of Telegram's approach to secure communication.

    Key Management System

    Telegram's MTProto 2.0 protocol incorporates advanced cryptographic techniques to safeguard messages:

    • 256-bit AES encryption for symmetric data protection

    • 2048-bit RSA encryption for secure key exchange

    • Diffie–Hellman key exchange to establish shared secrets

    Each message is encrypted with a unique 64-bit key identifier and a 128-bit message key, ensuring robust protection [27].

    Data Storage and Security

    Telegram's security framework extends beyond encryption. Decryption keys are split and distributed across multiple global data centres, each governed by different legal entities. This decentralised structure adds an extra layer of security, as accessing user data would require navigating various legal jurisdictions.

    Secret Chats Security

    In Secret Chats, encryption keys are generated and stored exclusively on users' devices. These chats include features like self-destruct timers and separate encryption for media files. Since messages never touch Telegram's servers, they remain entirely private and device-specific.

    Telegram's dual-encryption model highlights how key storage methods directly impact both data accessibility and user privacy.

    7. Facebook Messenger

    After reviewing Telegram, it's clear that Facebook Messenger has taken its own path in improving encryption key management. Meta now ensures end-to-end encryption (E2EE) is enabled by default for personal messages and calls.

    Encryption Implementation

    Facebook Messenger uses the Signal Protocol alongside its proprietary Labyrinth Protocol for encrypted storage. These systems work together to securely manage the large amounts of media shared on the platform.

    Key Storage and Management

    AspectDetails
    Key LocationKeys are stored directly on user devices.
    Backup OptionsUsers can choose a 6-digit PIN or a virtual key stored in cloud storage.
    Key ChangesKeys are updated during app reinstalls, phone resets, or data clearing.

    Encryption Coverage

    Despite the introduction of E2EE, certain communication types are not covered:

    • Community Chats for Facebook groups

    • Business messaging interactions

    • Marketplace conversations

    • Chat customisation features like themes, nicknames, and reactions [28].

    • Messages sent before E2EE became standard remain unencrypted [31].

    Data Access and Control

    While the content of messages is encrypted, Meta can still access metadata such as:

    • Message timing

    • Sender and recipient details

    • Account data

    • Social contact information [33].

    "After years of work rebuilding Messenger, we've updated the app with default end-to-end encryption for all personal calls and messages. Huge congrats to the team on making this happen."
    – Mark Zuckerberg, Meta CEO [32]

    Security Features

    Facebook Messenger also includes additional privacy-focused tools:

    • A 15-minute window for editing messages

    • Disappearing messages that vanish after 24 hours

    • Customisable read receipts [29].

    "Whether you're sharing family photos or your personal finances, end-to-end encryption allows all of your information to be shared with added privacy and security."
    – Meta [30]

    sbb-itb-a5875d1

    8. Signal

    Signal

    Signal is a messaging platform trusted by 70 million users worldwide for its strong end-to-end encryption (E2EE). Its primary focus is on ensuring user privacy and security at all times [34].

    Encryption Implementation

    Signal employs the Signal Protocol, a robust system built on three key components:

    • Double Ratchet Algorithm

    • Prekeys system

    • Triple elliptic‐curve Diffie–Hellman handshake [35]

    This protocol delivers:

    • Confidentiality of messages

    • Authentication of participants

    • Forward secrecy

    • Post-compromise security

    • Unlinkability of messages [35]

    Key Storage and Management

    Signal's approach to key management ensures maximum security:

    AspectImplementation
    Key LocationStored only on user devices
    Server AccessKeys are inaccessible to servers
    Message StorageKept exclusively on devices
    Identity VerificationManual fingerprint comparison required

    Security Features

    Signal incorporates several key features to enhance its security framework:

    FeaturePurpose
    Sealed SenderHides sender identity metadata
    Minimal Data CollectionCollects only what’s essential for transmission
    Open Source CodeAllows independent security audits
    Device-Specific KeysKeeps keys confined to individual devices

    Platform-Specific Considerations

    Signal adapts its security measures to different platforms:

    • Windows and Linux: The database encryption key requires extra safeguards against malware operating under the same user account [36].

    • MacOS: Security is bolstered through the keychain, which applies per-application access controls [36].

    • Mobile Platforms: Both iOS and Android versions implement secure key storage using isolated, controlled environments [36][38].

    These tailored measures enhance Signal’s encryption capabilities, though certain vulnerabilities persist.

    Security Limitations

    While Signal offers robust encryption, some limitations exist:

    • Users must manually authenticate communication partners to ensure security [37].

    • Initial messages sent without one-time prekeys may be susceptible to replay attacks [37].

    • The PQXDH protocol does not fully protect against potential quantum-based attacks [37].

    "Signal is designed to never collect or store any sensitive information. Signal messages and calls cannot be accessed by us or other third parties because they are always end-to-end encrypted, private, and secure."

    • Signal Company [34]

    "The reported issues rely on an attacker already having full access to your device - either physically, through a malware compromise, or via a malicious application running on the same device… This is not something that Signal can fully protect against. Nor do we ever claim to."

    • Meredith Whittaker, Signal President [36]

    9. Slack

    Slack

    Slack has established itself as a widely-used communication platform, boasting 38.8 million daily active users [41]. It employs encryption for data in transit and at rest, but its default key management is centralised unless organisations opt for Enterprise Key Management (EKM). This approach highlights Slack's practices around encryption and key management.

    Encryption Implementation

    Slack secures data through encryption during transit and while stored [39]. However, it does not offer end-to-end encryption, meaning Slack retains default access to encryption keys [40].

    Enterprise Key Management

    For organisations using Slack's Enterprise Grid, Enterprise Key Management (EKM) provides an additional layer of security [39]. EKM allows organisations to manage their own encryption keys using AWS Key Management Service (KMS). This setup also offers the flexibility to revoke access at detailed levels. Key features of EKM include:

    FeatureDetails
    Key StorageAWS Key Management Service (KMS)
    Access ControlGranular revocation options
    MonitoringLogging via AWS CloudWatch and CloudTrail
    Revocation ScopeControl by organisation, workspace, channel, time, or file

    Security Considerations

    High-profile incidents, like the Disney breach involving 1.1 terabytes of Slack data [43], highlight the risks associated with improper key management. Additionally, research shows that 1 in 166 Slack messages contains sensitive information [40]. These findings emphasise the importance of implementing strong security measures to protect Slack communications.

    Best Practices for Security

    "Private Channels Are Not Truly Private: In Enterprise Grid workspaces with compliance exports enabled, admins can access private channel and DM content." [41]

    To bolster security, organisations should consider the following measures:

    • Access Controls: Use robust multi-factor authentication (MFA) and enforce strict user permissions.

    • Integration Management: Carefully evaluate and monitor third-party applications.

    • Data Retention: Define clear policies for message storage and retention.

    • Token Security: Regularly rotate and securely store access tokens.

    • Mobile Security: Implement device management policies to secure mobile access.

    Industry Perspective

    The demand for stronger encryption is growing across the industry. In June 2023, over 90 companies formally urged Slack to introduce end-to-end encryption [42]. This push reflects a broader trend toward prioritising encryption key management in messaging platforms.

    10. Microsoft Teams

    Microsoft Teams

    Microsoft Teams has firmly established itself as a leader in enterprise communication, boasting over 320 million active users and adoption by 91% of Fortune 100 companies [49].

    Encryption Implementation

    Microsoft Teams secures its communication channels with robust encryption methods. Here's a breakdown of the encryption protocols used for various types of traffic:

    Traffic TypeEncryption Protocol
    Server-to-serverTLS with MTLS/Service-to-Service OAuth
    Client-to-server messagingTLS
    Media flowsTLS
    Audio/video sharingSRTP/TLS
    End-to-end encrypted callsSRTP/DTLS

    Key Management and Data Access

    Microsoft Teams employs different key management approaches tailored to service levels:

    • Standard Encryption: For standard services, Microsoft retains control of the encryption keys [44].

    • Customer Key Implementation: Organisations can use Customer Key to customise encryption:

    At the application level: Encrypting Teams files stored in SharePoint.

    • At the tenant level: Encrypting chats, media, recordings, notifications, and status updates [46].
    • End-to-End Encryption (E2EE): E2EE is available for one-to-one calls, safeguarding real-time media like audio, video, and screen sharing. However, features like recording and live captions are disabled when E2EE is enabled [44][45].

    These encryption strategies are a key part of Teams' comprehensive approach to data security.

    Data Protection Measures

    Microsoft processes an astonishing 8 trillion security signals daily [47]. The company emphasises that customers using Microsoft 365 or Office 365 retain full ownership and control over their data, which is only used to deliver the subscribed services [46].

    European Compliance

    Microsoft Teams adheres to strict European data protection regulations. Key measures include:

    • Storing data within EU/EFTA countries.

    • Implementing Standard Contractual Clauses.

    • Supporting GDPR compliance and accountability.

    • Pseudonymising personal data in system logs [3].

    Security Best Practices

    To maximise security when using Microsoft Teams, organisations should consider the following:

    • Activate multi-factor authentication.

    • Apply least-privilege access policies.

    • Regularly review and configure guest access settings.

    • Conduct employee training on security protocols.

    • Perform frequent audits of security configurations [48].

    Service Comparison

    Below is an overview comparing encryption models, key management, and GDPR compliance across various services.

    Storage Services Comparison

    ServiceEncryption ModelKey ManagementData StorageGDPR Compliance
    Microsoft OneDriveService encryption + volume encryptionMicrosoft-managed or Customer Key via Azure Key VaultEU/EFTA regionsGDPR compliant
    Google DriveTLS for transfers + AES-128 for storageGoogle-managed keysEU data centresGDPR compliant
    HypervaultEnd-to-end encryptionClient-side key managementEU-based storageGDPR compliant

    Messaging Services Comparison

    ServiceDefault EncryptionKey ControlEncrypted BackupsMetadata Access
    WhatsAppEnd-to-end (Signal protocol)User-controlled private keysOptional 64-digit encryption keyMinimal
    TelegramServer-client encryptionServer-side keysNot availableFull server access
    SignalEnd-to-end encryptionUser-controlledNot availableMinimal
    Microsoft TeamsTLS/MTLS encryptionMicrosoft-managed (Customer Key option available)Available with E5 licenceMinimal

    These tables highlight the core differences and security features of the services, setting the foundation for further analysis.

    Key Security Insights

    Some notable points include WhatsApp's ability to frequently update encryption keys and Microsoft's provision of flexible key management options.

    "The practical impact is that the vast majority of one-on-one Telegram conversations - and literally every single group chat - are probably visible on Telegram's servers."
    – Matthew Green, Cryptography Expert, Johns Hopkins University [50]

    Enterprise Considerations

    For organisations operating within the EU, the following points are crucial:

    • EU-based data storage with strong encryption ensures compliance with GDPR regulations.

    • Customer-managed key options offer greater control over sensitive data.

    • End-to-end encryption provides a higher level of security compared to server-side encryption.

    • Regular security audits and updates enhance overall system reliability and trustworthiness [51].

    Key Findings

    This analysis sheds light on the main challenges of encryption key management for Belgian users. Drawing from the service comparisons above, these findings aim to provide Belgian organisations with a strategic perspective. Below, we summarise key security features, potential risks, and strategies to address these issues, helping organisations make informed choices.

    End-to-End Encryption Implementation
    True end-to-end encryption - where users retain full control of their encryption keys - is rare among services. However, WhatsApp is a notable exception, as it uses end-to-end encryption by default for messages and calls, ensuring that neither WhatsApp nor third parties can access the content [21]. Gmail has also rolled out end-to-end encryption, preventing emails from being accessible to Google's servers [52].

    Security Risks and Vulnerabilities
    Approximately 25% of sensitive data remains publicly accessible, exposing users to risks like identity theft and financial fraud [53]. The primary risks include:

    • Provider-Side Vulnerabilities: These include attacks on infrastructure, insider threats, and compliance with government data requests [57].

    • Data Sovereignty Issues: Belgian organisations face the risk of foreign governments demanding access to their data [57][54].

    • Compliance Challenges: The Belgian Data Protection Authority stresses the importance of adhering to both the AI Act and GDPR when handling personal data [55]. Notably, only 67% of organisations currently encrypt their cloud-stored data [56].

    Mitigation Strategies
    To address these vulnerabilities, organisations can implement the following measures to strengthen data security:

    • Use client-side encryption with robust key management practices.

    • Rely on AES-256 encryption standards for enhanced protection.

    • Employ double-wrapping for encryption keys, where separate sets are managed by both the provider and the customer [58].

    As noted earlier, GDPR and Belgian regulatory requirements are driving demand for solutions that prioritise client-side encryption and data storage within the EU. This trend underscores the importance of effective encryption key management in safeguarding data sovereignty and ensuring privacy.

    How End-to-End Encryption Supports GDPR Compliance

    End-to-end encryption (E2EE) is a powerful tool for protecting personal data and aligning with GDPR requirements. It ensures that data is encrypted on the sender's device and can only be decrypted on the recipient's device. This means that even if the data is intercepted during transmission, it remains unreadable to anyone without the decryption key. By doing so, E2EE significantly lowers the risk of data breaches and unauthorised access.

    Under GDPR, organisations are required to implement technical measures to safeguard personal data. E2EE is widely recognised as an effective solution for meeting this obligation. Moreover, encrypted data is often exempt from breach notification requirements, as it is considered secure from unauthorised access. By adopting encryption practices, organisations can better protect individuals' privacy and ensure compliance with GDPR's stringent data protection standards.
    :::

    ::: faq

    How can organisations improve data security when using cloud storage services like OneDrive or Google Drive?

    How to Improve Data Security on Cloud Storage Platforms

    To keep data safe on cloud storage platforms, organisations should focus on a few key practices. First, always use strong encryption for your data - both when it's being transferred and when it's stored. This ensures sensitive information stays out of the wrong hands.

    Adding multi-factor authentication (MFA) and enforcing strong password policies can significantly boost security. These steps make it much harder for unauthorised users to break in. It's also important to regularly review access permissions and restrict access based on how sensitive the data is. This way, only the right people have access to the right information.

    By applying these measures together, organisations can better protect their cloud-stored data and stay aligned with security requirements.
    :::

    Frequently Asked Questions